
Security
Some information deserves more than a folder.
We describe our security plainly. We don't claim certifications, audits or guarantees we haven't actually completed.
Server-enforced authorization
Every record belongs to one Life Box. Access rules are enforced in the database and on the server, never by hiding buttons in the browser.
Private document storage
Files are never stored at public URLs. Documents are reached only through short-lived signed links tied to your signed-in account.
Stricter handling for secrets
Passwords, PINs and recovery codes are a separate item type. They are hidden by default, revealed intentionally, and kept out of analytics, notifications and ordinary AI indexing.
Strong authentication
Email and password with verification today, with multi-factor authentication, passkeys and session management as the product matures.
Audit trail
Consequential actions — sign-ins, will changes, representative changes, permission changes, secret reveals and exports — are recorded as immutable audit events.
Nothing unlocks automatically
No one gets access because they know your email, claim you died, or upload a copy of a will. Every access claim is reviewed by a person.
Data residency
We prefer Canadian data residency where practical, and we will not tell you your data never leaves Canada until every storage, backup, logging and processing vendor has been verified.
You can leave with your data
Export your Life Box at any time. Portability is part of the trust model.